WINSTON & MILLER

Articles

The DoD RMF process, step by step: what it takes to earn an ATO

Seven steps, one decision. Here is what each RMF step produces, who owns it, and where packages lose months.

Articles · · 7 min read · By Winston & Miller

An Authority to Operate is a risk decision, not a certificate. The authorizing official (AO) signs to accept the residual risk of running a system on a DoD network. Everything in the Risk Management Framework exists to give that official enough evidence to sign with confidence.

DoD implements RMF through DoD Instruction 8510.01, built on NIST SP 800-37 Revision 2. The work runs in seven steps, and most of the record lives in eMASS, the Enterprise Mission Assurance Support Service.

The seven RMF steps

StepWhat it produces
1. PrepareRoles assigned (AO, security control assessor, ISSM, ISSO, system owner), the authorization boundary, and organization-wide risk strategy.
2. CategorizeThe system's impact level for confidentiality, integrity and availability. DoD uses CNSSI 1253 for this.
3. SelectThe NIST SP 800-53 control baseline, tailored with overlays and documented in the System Security Plan (SSP).
4. ImplementControls built into the system and described as implemented, including STIG configuration.
5. AssessIndependent testing by the assessor, recorded in the Security Assessment Report (SAR).
6. AuthorizeThe AO's decision: ATO, ATO with conditions, an Interim Authority to Test (IATT), or denial.
7. MonitorContinuous monitoring, POA&M updates and change review that keep the authorization valid.

Where ATO packages stall

1. A boundary nobody agrees on

If the authorization boundary is vague, every later artifact is wrong. Interconnections get missed, inherited controls get claimed twice, and the assessor sends the package back. Settle the boundary diagram and the interconnection list in the Prepare step, and get the ISSM and system owner to sign it.

2. Control narratives that restate the control

An implementation statement that repeats the control text tells the assessor nothing. A good statement names who does what, with which tool, how often, and where the evidence lives. Assessors test what you say you do, so say exactly what you do.

3. Scan results that don't match the POA&M

The ACAS findings, the STIG checklists and the POA&M must tell one story. When a scan shows a finding the POA&M doesn't carry, the assessor stops trusting the rest of the package. Reconcile all three before you submit.

4. Treating authorization as the finish line

Programs that sprint to the signature and then stop monitoring end up re-authorizing from scratch. The Monitor step is where an ATO is kept. We cover that operating model in our white paper, Keeping the ATO.

Who does the work

The ISSO carries most of the daily load: maintaining the SSP, tracking POA&M items, reviewing changes for security impact and keeping eMASS current. The ISSM oversees one or more systems and ties them to the organization's risk posture. When those seats are filled with senior practitioners, the package reaches the assessor clean the first time.

Winston & Miller's founder spent more than eight years as a Senior ISSO and Navy Qualified Validator running RMF A&A in eMASS for a Naval aviation RDT&E enterprise.

Sources: NIST SP 800-37 Rev. 2 · DoD Instruction 8510.01 (DoD Issuances) · NIST SP 800-53 Rev. 5

  • Risk Management Framework
  • RMF
  • ATO
  • Authority to Operate
  • eMASS
  • DoDI 8510.01
  • NIST SP 800-37
  • NIST SP 800-53
  • ISSO
  • ISSM

Need this done on your program?

Winston & Miller supports primes and program offices across the National Capital Region with RMF, ATO, ISSO/ISSM and CMMC work.

Request a capability statement